01 Does DORA apply to us if we are not a financial entity?
Directly, almost certainly not. Article 2(1)(u) lists ICT third-party service providers among the entities the Regulation applies to, but Article 2(2) reserves the term “financial entity” for points (a) to (t), and the direct oversight regime in Chapter V applies only to providers designated as critical under Article 31. Nineteen firms were designated on 18 November 2025. Everyone else is reached through the contract clauses Article 30 obliges the financial entity to impose.
02 What is the difference between Article 30(2) and Article 30(3)?
Article 30(2) sets nine elements that must appear in every contractual arrangement on the use of ICT services with a financial entity. Article 30(3) adds six more, and applies only where the ICT services support a critical or important function. Paragraph 3 is cumulative: a critical-function contract carries all fifteen. The six additions are quantitative service levels, material-change notification, tested contingency plans, TLPT participation, unrestricted access and audit rights, and an exit strategy with a mandatory transition period.
03 Who decides whether our service supports a critical or important function?
The financial entity, before it contracts, under Article 28(4)(a). The definition in Article 3(22) measures impairment at the financial entity, not at the supplier, so it is about what the customer uses the service for. The determination can change during the life of the contract: Article 28(3) requires the entity to tell its competent authority when a function has become critical or important. Ask for the classification in writing before signature.
04 Can a bank really force us into a red team test of our own production systems?
If the contract falls under Article 30(3), yes, by the clause it obliges the bank to include. Article 30(3)(d) requires participation and full cooperation in the financial entity’s TLPT. Article 26(2) requires the test to run on live production systems and requires the entity to identify underlying systems supporting critical or important functions, including those contracted to providers. Delegated Regulation (EU) 2025/1190 sets an active red team phase of at least 12 weeks.
05 Is there a way to avoid a separate red team exercise for every bank customer?
Article 26(4) is the route. Where your participation would be reasonably expected to adversely affect the quality or security of services you deliver to customers outside DORA, or the confidentiality of their data, you and the financial entity may agree in writing that you contract the external tester directly for a pooled TLPT covering several of your financial customers, under the direction of one designated entity. The pooled test counts as TLPT carried out by every participating entity. It is an agreement, not a right, so propose it early.
06 Can we cap or refuse the audit rights?
Not in a critical-function contract. Article 30(3)(e)(i) requires unrestricted rights of access, inspection and audit whose effective exercise is “not impeded or limited by other contractual arrangements or implementation policies”. The one hinge in the text is point (ii), which lets the parties agree alternative assurance levels where other clients’ rights are affected. Refusal is worse than useless: under Delegated Regulation (EU) 2024/1773, Article 6(1)(e), your consent to effective on-site audits is assessed during due diligence, before the contract exists.
07 We are ISO/IEC 27001 certified. Is that enough?
No, and the reason is written down. Delegated Regulation (EU) 2024/1773, Article 8(3) states that the financial entity “shall not over time rely solely on certifications … or audit reports”. Reliance is conditional on eight further tests, including that the scope covers the systems and key controls the entity itself identified, that the report is not obsolete, that the audit tested the operational effectiveness of key controls, and that the entity keeps the right to run its own individual and pooled audits at its discretion. A certificate shortens the conversation; it does not end it.
08 What happens to our own subcontractors?
Delegated Regulation (EU) 2025/532 pushes the regime one level down. The contract must identify which critical-function services may be subcontracted and on what conditions, make you responsible for the services your subcontractors provide, and require that your subcontractors grant the financial entity and the authorities the same rights of access, inspection and audit. Article 5 goes further: you must notify intended material changes to your subcontracting and may only implement them after the financial entity has approved or not objected within the notice period.
09 Why do we get a data request every February?
Because of the register of information. Article 28(3) requires every financial entity to maintain a register of all its ICT contracts and file it with its supervisor. Implementing Regulation (EU) 2024/2956 sets the templates and requires an LEI or EUID for you and, where the service supports a critical or important function, for the subcontractors underpinning it. Latvijas Banka states that entities file annually by 1 March using the previous 31 December data, so the questionnaire reaches you in the weeks before that.
10 Does DORA make our staff sit the bank’s security training?
It makes the contract address the question. Article 30(2)(i) requires the contract to set out “the conditions for the participation of ICT third-party service providers in the financial entities’ ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6)”. Article 13(6) obliges financial entities to run those programmes as compulsory modules for their own staff and says they “shall also include ICT third-party service providers in their relevant training schemes” where appropriate. So the extent is negotiable; the presence of the clause is not.